[SERVER-74999] Create configuration file option for custom X.509 extension for cluster membership Created: 17/Mar/23  Updated: 29/Oct/23  Resolved: 03/Apr/23

Status: Closed
Project: Core Server
Component/s: None
Affects Version/s: None
Fix Version/s: 7.0.0-rc0

Type: Task Priority: Major - P3
Reporter: Varun Ravichandran Assignee: Sara Golemon
Resolution: Fixed Votes: 0
Labels: auto-reverted
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Documented
is documented by DOCS-15999 Investigate changes in SERVER-74999: ... Closed
Duplicate
is duplicated by SERVER-14655 x.509 certificate authentication requ... Closed
Problem/Incident
Assigned Teams:
Server Security
Backwards Compatibility: Minor Change
Sprint: Security 2023-04-03, Security 2023-04-17
Participants:
Linked BF Score: 0

 Description   

Define an X.509 extension that should explicitly be set on certificates when the clusterMembershipExtension configuration option is specified. All connecting clients that provide a certificate with that extension set to the value of clusterMembershipExtension will be treated as peer servers provided that the host server is configured to handle X.509 auth.



 Comments   
Comment by Githook User [ 03/Apr/23 ]

Author:

{'name': 'Sara Golemon', 'email': 'sara.golemon@mongodb.com', 'username': 'sgolemon'}

Message: SERVER-74999 Determine cluster membership based on X.509 extension
Branch: master
https://github.com/mongodb/mongo/commit/dc2ff7aa916ef1412ea939b0eaf49a063665d309

Comment by xgen-buildbaron-user [ 01/Apr/23 ]

Ticket re-opened due to revert. external_auth began a consistent failure of src/mongo/db/modules/enterprise/jstests/external_auth/ldap_authz_runtime_parameters.js,src/mongo/db/modules/enterprise/jstests/external_auth/ldap_authz_query.js,src/mongo/db/modules/enterprise/jstests/external_auth/ldap_user_mapping.js

Comment by Githook User [ 01/Apr/23 ]

Author:

{'name': 'auto-revert-processor', 'email': 'dev-prod-dag@mongodb.com', 'username': ''}

Message: Revert "SERVER-74999 Determine cluster membership based on X.509 extension"

This reverts commit 2dcf180fa810ec81054db8249337255495e41647.
Branch: master
https://github.com/mongodb/mongo/commit/128fe164fb93ef1233158019e59f43570f6e0df0

Comment by Githook User [ 31/Mar/23 ]

Author:

{'name': 'Sara Golemon', 'email': 'sara.golemon@mongodb.com', 'username': 'sgolemon'}

Message: SERVER-74999 Determine cluster membership based on X.509 extension
Branch: master
https://github.com/mongodb/mongo/commit/2dcf180fa810ec81054db8249337255495e41647

Generated at Thu Feb 08 06:29:04 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.